Back to Guides
Guide7 October 2026

How to Fix a Missing Content - Security - Policy Header

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. Why does a missing Content - Security - Policy header matter?
  3. How do I add a Content - Security - Policy header on my server?
  4. Should I start with Report - Only mode?
  5. How can I build a baseline enforcing policy?
  6. What should I do about inline scripts and styles?
  7. How do I verify that the CSP header is correctly deployed?
  8. What next after the header is working?
  9. How does Decloak help fix CSP issues?

Key takeaways

Why does a missing Content - Security - Policy header matter?

A missing CSP header leaves the browser without guidance on which resources are allowed, making it easy for attackers to inject malicious scripts. Adding CSP blocks many cross - site scripting attacks and reduces the impact of content injection flaws.

How do I add a Content - Security - Policy header on my server?

Configure your web server, reverse - proxy, or application framework to send the header in every response. For Nginx use add_header Content - Security - Policy "...";. For Apache add Header always set Content - Security - Policy "..." in .htaccess or the VirtualHost. Frameworks such as Express can use Helmet, Django can use django - csp, and Flask can use Flask - Talisman.

Should I start with Report - Only mode?

Yes. Deploy Content - Security - Policy - Report - Only first so browsers report violations without blocking content. Example header:

Content - Security - Policy - Report - Only: default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self'; font-src 'self'; connect-src 'self'; frame-ancestors 'none'; report-uri /csp-violations

Collect reports for a few days, then use the data to tighten the enforcing policy.

How can I build a baseline enforcing policy?

Start with a permissive but explicit baseline and add sources only as needed. A common starting point:

Content - Security - Policy: default-src 'self';
script-src 'self' https://cdn.example.com https://www.google-analytics.com;
style-src 'self' 'unsafe-inline' https://fonts.googleapis.com;
img-src 'self' data: https:;
font-src 'self' https://fonts.gstatic.com;
connect-src 'self' https://api.example.com https://www.google-analytics.com;
frame-ancestors 'self';
base-uri 'self';
form-action 'self';
upgrade-insecure-requests

Adjust each directive based on the violation reports you gathered.

What should I do about inline scripts and styles?

Replace inline code with nonces or hashes. Generate a unique nonce per response and add it to the CSP header, e.g., script-src 'self' 'nonce-<random>'. If replacement is impossible, limit 'unsafe-inline' to the specific directives that need it and keep it off everywhere else.

How do I verify that the CSP header is correctly deployed?

Run a simple curl command and look for the header:

curl -sI https://example.com | grep -i "content-security-policy"

Check the browser developer tools console for CSP warnings or violations. Optionally run an online scanner such as Decloak's free scan to confirm the header appears and that no CSP - related findings remain.

What next after the header is working?

Monitor the report - only logs for a week to ensure no legitimate content is blocked. Then remove the Report - Only header and keep the enforcing CSP. Periodically re - run scans, especially after adding new third - party scripts or changing the site architecture.

How does Decloak help fix CSP issues?

Decloak's free scan checks the HTTP/TLS posture layer and reports a missing CSP header as a finding. The scan also shows the current header value (if present) and provides a graded recommendation, helping you confirm that your fix resolves the issue.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary